Description
ext/mysqlnd/mysqlnd.c in PHP before 5.4.43, 5.5.x before 5.5.27, and 5.6.x before 5.6.11 uses a client SSL option to mean that SSL is optional, which allows man-in-the-middle attackers to spoof servers via a cleartext-downgrade attack, a related issue to CVE-2015-3152.
Remediation
References
Related Vulnerabilities
WordPress Plugin Recart-The New GhostMonitor Unspecified Vulnerability (1.5.0)
MySQL CVE-2023-21972 Vulnerability (CVE-2023-21972)
WordPress Plugin article2pdf Multiple Vulnerabilities (0.27)
WordPress Plugin Popup by Supsystic Cross-Site Scripting (1.10.4)
WordPress Plugin Booking Calendar Contact Form Multiple Vulnerabilities (1.0.2)